Extension WordPress
Vulnérabilités Atarim – Visual Feedback, Review & AI Collaboration
Cette page rassemble les failles publiées pour Atarim – Visual Feedback, Review & AI Collaboration, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Atarim – Visual Feedback, Review & AI Collaboration
20 fiches
Atarim <= 4.3.2 – Missing Authorization
The Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-4.3.2
4.3.3
08/03/2026
Atarim <= 4.2.1 – Missing Authorization
The Visual Feedback, Review & AI Collaboration Tool For WordPress – Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.1. This…
*-4.2.1
4.2.2
09/02/2026
Atarim <= 4.0.9 – Missing Authorization to Unauthenticated Arbitrary Post Deletion
The Atarim – Visual Feedback, Review & AI Collaboration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.9. This makes it possible…
*-4.0.9
4.1.0
03/02/2026
Atarim <= 4.3.1 – Missing Authorization
The Visual Feedback, Review & AI Collaboration Tool For WordPress – Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.3.1. This…
*-4.3.1
4.3.2
30/01/2026
Atarim <= 4.2.1 – Unauthenticated Information Exposure
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to extract sensitive user…
*-4.2.1
4.2.2
15/09/2025
Atarim <= 4.2.1 – Unauthenticated Information Exposure
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to extract sensitive user…
*-4.2.1
4.2.2
29/07/2025
Atarim <= 4.2.1 – Unauthenticated Arbitrary File Upload
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.2.1. This makes it possible for…
*-4.2.1
4.2.2
29/07/2025
Atarim <= 4.2.1 – Unauthenticated Privilege Escalation
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to elevate their privileges to…
*-4.2.1
4.2.2
27/07/2025
Atarim <= 4.1.0 – Reflected Cross-Site Scripting
The Atarim plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-4.1.0
4.1.1
23/02/2025
Atarim <= 4.0.8 – Unauthenticated Stored Cross-Site Scripting
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it…
*-4.0.8
4.0.9
24/01/2025
Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 – Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and…
*-4.0.9
4.1.0
20/01/2025
Atarim <= 4.0.1 – Missing Authorization via remove_feedbacktool_notice()
The Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_feedbacktool_notice() function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to dismiss…
*-4.0.1
4.0.2
16/08/2024
Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.2 – Missing Authorization to Authenticated (Subscriber+) Settings Update
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_wpfeedback_misc_options() function in all versions up to, and including, 4.0.2.…
*-4.0.2
4.0.3
09/08/2024
Atarim <= 4.0 – Missing Authorization
The Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-4.0
4.0.1
19/07/2024
Atarim <= 3.31 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.31 due to insufficient input sanitization and output escaping.…
*-3.31
3.32
28/06/2024
Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.30 – Unauthenticated Stored Cross-Site Scripting
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comments in all versions up to, and including, 3.30 due to insufficient input sanitization and output escaping. This…
*-3.30
3.31
30/05/2024
Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.22.6 – Hardcoded Credentials
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credentials to authenticate all…
*-3.22.6
3.30
22/05/2024
Atarim <= 3.12 – Unauthenticated Cross-Site Scripting
The Atarim plugin for WordPress is vulnerable to Cross-Site Scripting via the new_task parameter in versions up to, and including, 3.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-3.12
3.13
07/11/2023
Atarim <= 3.9.3 – Reflected Cross-Site Scripting
The Atarim plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_graphics_excerpt' parameter in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.9.3
3.9.4
10/08/2023
Atarim – Client Interface <= 3.9.1 – Missing Authorization via AJAX actions
The Atarim – Client Interface plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the avc_send_invitations and avc_delete_invitations functions in versions up to, and including, 3.9.1. This makes it possible…
[*, 3.9.2)
3.9.2
07/07/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.